[PATCH 07/27] gpu: nova-core: add optional ucodes firmware loading

From: John Hubbard

Date: Tue Aug 18 2026 - 23:54:40 EST


The new GSP firmware takes an optional ucodes image, a bindata blob of
microcode that GSP-RM loads at runtime. Open RM fetches it for every
chip family except GB10Y and fails firmware load without it, so the
driver will require it too once it boots the new firmware. The helper
added here reports a missing metadata file rather than failing, and
leaves that policy to its caller.

Load the ucodes metadata with the existing TLV request helper, and add
support for the generic TLV payload convention it uses: either an inline
BLOB, or a FILE basename with its SIZE. A FILE tag may only name a
basename in the metadata file's own directory, so one carrying a path
separator, a special directory name, or a control byte is rejected.
Nothing calls this until the driver switches to the new firmware.

Assisted-by: Cursor:claude-opus-5
Signed-off-by: John Hubbard <jhubbard@xxxxxxxxxx>
---
drivers/gpu/nova-core/firmware.rs | 8 +++-
drivers/gpu/nova-core/firmware/bindata.rs | 38 +++++++++++++++
drivers/gpu/nova-core/firmware/tlv.rs | 56 +++++++++++++++++++++++
3 files changed, 101 insertions(+), 1 deletion(-)
create mode 100644 drivers/gpu/nova-core/firmware/bindata.rs

diff --git a/drivers/gpu/nova-core/firmware.rs b/drivers/gpu/nova-core/firmware.rs
index 34657004568c..dfd41364cc77 100644
--- a/drivers/gpu/nova-core/firmware.rs
+++ b/drivers/gpu/nova-core/firmware.rs
@@ -22,6 +22,7 @@
num::IntoSafeCast, //
};

+pub(crate) mod bindata;
pub(crate) mod booter;
pub(crate) mod fsp;
pub(crate) mod fwsec;
@@ -348,7 +349,12 @@ const fn make_entry_chipset(self, chipset: gpu::Chipset) -> Self {
let mut this = self
.make_entry_file(name, "gsp_bootloader.tlv")
.make_entry_file(name, "gsp.tlv")
- .make_entry_file(name, "gsp.bin");
+ .make_entry_file(name, "gsp.bin")
+ .make_entry_file(name, "ucodes.tlv")
+ // `ucodes.tlv` may name another safe basename in its FILE tag, but module firmware
+ // metadata cannot describe a runtime-selected filename. Advertise the conventional
+ // filename used by the distributed metadata.
+ .make_entry_file(name, "ucodes.bin");

// Add the firmware files specific to the GSP boot method of `chipset`.
let boot_files = boot_firmware_files(chipset);
diff --git a/drivers/gpu/nova-core/firmware/bindata.rs b/drivers/gpu/nova-core/firmware/bindata.rs
new file mode 100644
index 000000000000..d9625ab7d738
--- /dev/null
+++ b/drivers/gpu/nova-core/firmware/bindata.rs
@@ -0,0 +1,38 @@
+// SPDX-License-Identifier: GPL-2.0
+// SPDX-FileCopyrightText: Copyright (c) 2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
+
+//! GSP bindata firmware loading.
+
+use kernel::{
+ device,
+ prelude::*, //
+};
+
+use crate::{
+ firmware::tlv::{
+ request_tlv,
+ Tlv, //
+ },
+ gpu::Chipset,
+};
+
+/// Requests the optional `ucodes` bindata metadata and loads its payload.
+///
+/// A missing metadata file is reported as [`None`] so that the eventual caller can decide whether
+/// ucodes are optional for its boot path. Once the metadata has been found, all parse and payload
+/// loading errors, including a missing referenced file, are returned as errors.
+#[expect(dead_code)]
+pub(crate) fn request_ucodes_firmware(
+ dev: &device::Device,
+ chipset: Chipset,
+) -> Result<Option<VVec<u8>>> {
+ let firmware = match request_tlv(dev, chipset, "ucodes") {
+ Ok(firmware) => firmware,
+ Err(e) if e == ENOENT => return Ok(None),
+ Err(e) => return Err(e),
+ };
+
+ let tlv = Tlv::new(firmware.data())?;
+
+ Ok(Some(tlv.load_blob_or_file(dev, chipset)?))
+}
diff --git a/drivers/gpu/nova-core/firmware/tlv.rs b/drivers/gpu/nova-core/firmware/tlv.rs
index 7b879f13a61e..b9aabf9ee952 100644
--- a/drivers/gpu/nova-core/firmware/tlv.rs
+++ b/drivers/gpu/nova-core/firmware/tlv.rs
@@ -198,6 +198,62 @@ fn iter(&self) -> TlvIter<'_, 'a> {
self.iter().find(|b| b.tag == *tag).ok_or(EINVAL)
}

+ fn contains(&self, tag: &[u8; 4]) -> bool {
+ self.iter().any(|b| b.tag == *tag)
+ }
+
+ /// Loads the payload described by this TLV into owned memory.
+ ///
+ /// The generic firmware TLV representation is either an inline `BLOB`, or a `FILE` basename
+ /// together with its `SIZE`. Mixing the representations or specifying only half of the file
+ /// representation is invalid. Referenced files are constrained to the metadata file's
+ /// directory.
+ pub(crate) fn load_blob_or_file(
+ &self,
+ dev: &device::Device,
+ chipset: gpu::Chipset,
+ ) -> Result<VVec<u8>> {
+ let has_blob = self.contains(b"BLOB");
+ let has_file = self.contains(b"FILE");
+ let has_size = self.contains(b"SIZE");
+
+ match (has_blob, has_file, has_size) {
+ (true, false, false) => {
+ let blob = self.get_bytes(b"BLOB")?;
+ let mut data = VVec::with_capacity(blob.len(), GFP_KERNEL).map_err(|_| ENOMEM)?;
+ data.extend_from_slice(blob, GFP_KERNEL)?;
+ Ok(data)
+ }
+ (false, true, true) => {
+ let file = self.get_string(b"FILE")?;
+
+ // FILE is a basename relative to the TLV's directory, not an arbitrary firmware
+ // path. Reject path separators, special directory names, NULs and control bytes.
+ if file.is_empty()
+ || matches!(file, "." | "..")
+ || file
+ .bytes()
+ .any(|b| b == b'/' || b == b'\\' || b.is_ascii_control())
+ {
+ return Err(EINVAL);
+ }
+
+ let size = usize::from_safe_cast(self.get_u32(b"SIZE")?);
+ if size == 0 {
+ return Err(EINVAL); // TODO: Use ENODATA once available.
+ }
+
+ let mut data = VVec::zeroed(size, GFP_KERNEL).map_err(|_| ENOMEM)?;
+ let chip_name = chipset.name();
+ let path = CString::try_from_fmt(fmt!("nvidia/{chip_name}/gsp/{file}"))?;
+ firmware::request_into_buf(&path, dev, data.as_mut_slice())?;
+
+ Ok(data)
+ }
+ _ => Err(EINVAL),
+ }
+ }
+
/// Return a slice of bytes.
///
/// Returns `EINVAL` if the value is empty.
--
2.55.0